Description
A missing permission check in Jenkins Mercurial Plugin 2.11 and earlier allows attackers with Overall/Read permission to obtain a list of names of configured Mercurial installations.
Remediation
References
https://www.jenkins.io/security/advisory/2020-11-04/#SECURITY-2104
Related Vulnerabilities
CVE-2016-1181 Vulnerability in maven package struts:struts
CVE-2021-32620 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2013-6447 Vulnerability in maven package org.jboss.seam:jboss-seam-remoting
CVE-2014-0193 Vulnerability in maven package org.onosproject:onos-netconf-provider-device